In Depth
Enacted as Colorado SB 24-205 and signed in 2024, the Act targets high-risk AI systems, meaning those that make, or are a substantial factor in making, a consequential decision affecting a consumer in areas like employment, lending, housing, education, healthcare, insurance, and legal services. For those systems, the law imposes a duty of reasonable care to protect consumers against algorithmic discrimination, and it splits responsibilities between the developer who builds the system and the deployer who puts it to use.
In practice the duty translates into documentation, disclosure, and risk-management expectations: telling consumers when a high-risk system is used in a decision about them, maintaining impact assessments, and being able to show the steps taken to identify and reduce discriminatory outcomes. The reasonable-care framing matters because it's a negligence-style standard, so what counts as compliant turns on whether you took the kinds of precautions a careful operator would. That makes evidence of governance, not just good intentions, the thing that protects you.
The Act takes effect in 2026. What matters more is what it signals: with no single federal AI law, states are legislating one at a time, and Colorado is the template others are drafting against. A vendor selling into multiple states is heading toward a quilt of overlapping, non-identical obligations rather than one rule to satisfy.
What It Looks Like
A vendor's AI agent helps a lender decide which applicants to approve. Because a lending decision is a consequential decision under the Act, the agent is a high-risk system, and both the vendor (developer) and the lender (deployer) pick up duties. The lender has to disclose the AI's role to applicants and maintain its impact assessment; the vendor has to supply the documentation that makes that possible and show it exercised reasonable care against discriminatory outcomes. A single rejected applicant's complaint can put both parties' reasonable-care story to the test.
Why It Matters For AI Vendors
The deployer obligations mean your enterprise customers are now regulated parties when they use your agent, and they will push their obligations upstream to you in the contract. They need your documentation and your testing records to meet their own duty of care. A vendor who can't supply them becomes the weak link that stalls the deal.
The patchwork makes it worse. Colorado is first, not last. A vendor selling nationally can't build to one statute and forget it; the obligations vary by state and arrive on different timelines. Tracking that by hand, across a growing list of laws, is exactly the kind of work that slips until a complaint forces it.